Privacy Policy
Last updated: August 9, 2026
This Privacy Policy explains how XBio ("we", "us", "our") collects, uses, and protects your information when you use our service at xbio.gg.
1. Information We Collect
Account data: Name, email address, and profile picture (via OAuth providers or direct signup).
Profile content: Username, bio, links, theme configuration, and any media you upload.
Usage analytics: Page views, link clicks, referrer URLs, country, and device type, stored in our database and associated with the profile that was visited. Visitor IP addresses are not stored: the address is converted to an irreversible keyed hash the moment a request arrives, and only that hash is written. We use it solely to tell repeat visits apart - so a single visit isn't counted twice and XP can't be farmed - never to identify anyone. Note that a hash of this kind is still treated as personal data under the GDPR; what it prevents is anyone reading addresses out of our database.
Payment data: Payment processing is handled by Stripe. We store a Stripe Customer ID but never see or store your raw card numbers.
Email subscribers: If you use the email capture feature on your profile, subscriber email addresses are stored in our database and are accessible only to you.
2. How We Use Your Information
- Provide, operate, and improve the Service
- Process payments and manage your subscription
- Send transactional emails (verification, password reset, purchase receipts)
- Send the welcome email on signup
- Calculate profile analytics and XP for gamification
- Enforce our Terms of Service and prevent abuse
- Detect, investigate and fix errors, crashes and security faults
3. Third-Party Services
We use the following third-party services that may process your data:
- Neon (neon.tech) - Serverless PostgreSQL database provider. All user data is stored on Neon infrastructure.
- Stripe (stripe.com) - Payment processing. Stripe's privacy policy governs payment data. We receive only a customer ID and payment status.
- Resend (resend.com) - Transactional email delivery. Your email address is shared with Resend to deliver verification and notification emails.
- Slack - We send ourselves internal notifications (via a Slack incoming webhook) when you sign up or make a purchase, which include your name and email address. These notifications go only to our private admin workspace - Slack does not otherwise process or store your account data.
- Sentry (sentry.io) - Error monitoring, session replay and performance tracing, which we treat separately:
- Error monitoring runs for all visitors, including those who decline the cookie banner. It captures browser type, the page URL and partial stack traces. It sets no cookies and uses no device storage. We rely on legitimate interest (Art. 6(1)(f) GDPR) in keeping the service working and secure. To minimize what is sent, IP address collection is disabled and every report is stripped of email addresses, access tokens and session cookies before it leaves our servers.
- Session replay and performance tracing only run if you accept non-essential cookies. Replay records a playback of your session when an error occurs and uses your browser's session storage. Declining, or not choosing, keeps both off.
- Vercel (vercel.com) - Hosting and deployment. Vercel Analytics may collect aggregate page view statistics and Core Web Vitals data. Only runs if you accept non-essential cookies in the cookie banner.
- Google / GitHub OAuth - If you sign in via Google or GitHub, your name, email, and profile picture are provided to us by those services under their respective privacy policies.
- Cloudflare Turnstile - Bot/spam protection on signup. Your IP address is sent to Cloudflare to verify you're human; no cookies or tracking scripts are used.
- Vercel Blob Storage - Uploaded files (avatars, banners) are stored on Vercel's blob storage service.
4. Cookies
We set the following cookies:
- xbio.session_token - Authentication session cookie. Required for login. Expires with your session or after 30 days.
- Theme preference - Stores your light/dark mode preference. No expiry.
Third-party cookies may be set by Stripe.js when you make a purchase, and by Vercel Analytics/Speed Insights and Sentry Session Replay - but only if you accept non-essential cookies in the cookie banner; declining or not choosing keeps those off. Sentry error monitoring is not in this group: it uses no cookies or device storage at all (see section 3). We do not use advertising cookies. For a full list, see our Cookie Policy.
5. Data Retention
We retain your account data for as long as your account is active. Analytics events (views, clicks) are retained for 90 days, after which they're automatically deleted - and they contain hashed visitor identifiers rather than IP addresses for that whole period. You can request deletion at any time.
6. Email Lists You Collect
If you enable email capture, the subscribers who sign up on your profile are your contacts, not ours. For those addresses you are the data controller and we act as your processor: we store them, and we send on your behalf when you use blasts or drip campaigns.
That makes some obligations yours, not ours. You must have a lawful basis for contacting the people who subscribe, only send them what they signed up for, and comply with applicable anti-spam law (including GDPR and CAN-SPAM). Every email we send on your behalf carries an unsubscribe link, and unsubscribes are honoured automatically - you may not attempt to defeat or remove that. We may suspend sending for any account that generates significant spam complaints or bounce rates, because delivery for every other user on the platform depends on our sending reputation.
We do not market to your subscribers, sell them, or use them for any purpose other than delivering the messages you send.
7. Outbound Webhooks
Pro users can configure webhooks that send events from their profile - profile views, link clicks, new subscribers, and milestones - to a URL of their choosing. Where you set one up, that data leaves our systems and is transmitted to a third-party endpoint you control and are responsible for. Depending on the event, the payload can include a subscriber's email address and coarse visitor information. We do not control what the receiving service does with it, so only point a webhook at somewhere you trust and are entitled to send that data.
8. Your Rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access - Request a copy of the personal data we hold about you
- Portability - Receive your data in a structured, machine-readable format
- Erasure - Request deletion of your account and all associated data
- Rectification - Correct inaccurate personal data
- Objection - Object to processing of your personal data, including the error monitoring we carry out under legitimate interest (section 3)
To exercise these rights, email privacy@xbio.gg with subject "Data Request".
9. Data Security
We implement appropriate technical measures including HTTPS encryption, hashed passwords, and database access controls. No method of transmission is 100% secure; use the Service at your own risk.
10. Children
The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe we have, contact us immediately.
11. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or a notice on the Service. Continued use after changes constitutes acceptance.
12. Contact
Questions about this policy? Contact us at privacy@xbio.gg or visit our Contact page.